{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2023-3417", "assignerOrgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe", "state": "PUBLISHED", "assignerShortName": "mozilla", "dateReserved": "2023-06-26T17:25:53.967Z", "datePublished": "2023-07-24T10:09:37.591Z", "dateUpdated": "2025-12-18T15:22:50.216Z" }, "containers": { "cna": { "affected": [ { "product": "Thunderbird", "vendor": "Mozilla", "versions": [ { "lessThan": "115.0.1", "status": "affected", "version": "unspecified", "versionType": "custom" } ] }, { "product": "Thunderbird", "vendor": "Mozilla", "versions": [ { "lessThan": "102.13.1", "status": "affected", "version": "unspecified", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "value": "Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1 and Thunderbird < 102.13.1." } ] } ], "title": "File Extension Spoofing using the Text Direction Override Character", "references": [ { "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1835582" }, { "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00032.html" }, { "url": "https://www.debian.org/security/2023/dsa-5463" }, { "url": "https://www.mozilla.org/security/advisories/mfsa2023-27/" }, { "url": "https://www.mozilla.org/security/advisories/mfsa2023-28/" } ], "credits": [ { "lang": "en", "value": "이준성 (Junsung Lee)" } ], "providerMetadata": { "orgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe", "shortName": "mozilla", "dateUpdated": "2025-12-18T15:22:50.216Z" } }, "adp": [ { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T06:55:03.371Z" }, "title": "CVE Program Container", "references": [ { "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1835582", "tags": [ "x_transferred" ] }, { "url": "https://www.mozilla.org/security/advisories/mfsa2023-27/", "tags": [ "x_transferred" ] }, { "url": "https://www.mozilla.org/security/advisories/mfsa2023-28/", "tags": [ "x_transferred" ] }, { "url": "https://www.debian.org/security/2023/dsa-5463", "tags": [ "x_transferred" ] }, { "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00032.html", "tags": [ "x_transferred" ] } ] }, { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-10-25T18:54:00.544708Z", "id": "CVE-2023-3417", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-25T18:54:26.256Z" } } ] } }